Grade a public repository
Paste a public GitHub repository and get a letter from A to F with the number of critical, high, medium and low issues in its code and dependencies. No account. The grade never names a file or a finding, and it comes with a README badge.
Grades can't be requested on this server: its access to GitHub isn't set up. Grades already asked for are still shown on their pages.
How the grade works
- A
- Nothing medium or above
- B
- Medium issues only
- C
- One or two high issues
- D
- Three or more high issues
- F
- At least one critical issue
Leaked secrets, such as API keys found in the code, are never counted in a grade or shown here: they are for the owner to rotate privately. So a grade says nothing about them.
- A grade counts the issues one complete scan of a commit on the default branch found in the code and its dependencies, by severity, one per issue. A scan that stopped early, lost coverage or left part of the code out never gives a grade. The page shows the letter, the counts, the commit and the date, and never a finding or a file path.
- Issues the owner marked false positive aren't counted, and the grade says how many there were. Low-confidence findings nobody confirmed aren't counted either.
- An organization that links its repository to LaunchSafe can claim it. Its grade then comes from its own code scans, and it decides whether the grade is shown and listed on the leaderboard. A newer grade with more critical or high issues is published up to 14 days later, so the owner can fix them first.
- Grades for repositories nobody has claimed come from LaunchSafe's free check. It scans the public repository at its newest commit, usually within a few minutes, and keeps only counts, never a file or a finding.
Want the issues themselves? An account shows each one with its file, its evidence and a fix pull request. Sign up, or see the leaderboard of repositories their owners chose to list.